safety: disable deploy workflows on Windy Git before they can fire
Six workflows deploy to production on push:. Windy Git now has a working runner, so the next synced commit to main would have attempted a production deploy FROM VERON 1. Their secrets are unset here so they would have failed — but loudly, on every push, with any pre-SSH step still running. All six now disabled_manually. Tests, lints and migration checks stay active: they need no secrets, which is exactly why Phase 1 delivers CI value with nothing to configure. Same class of mistake as the push-mirror direction, caught before firing this time rather than after. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@@ -58,6 +58,26 @@ three ways, two sessions recording different HEADs hours apart. Resolve which is
|
||||
current and write it down before importing (G11.5). The import script refuses it
|
||||
by name.
|
||||
|
||||
## ⚠️ Deploy workflows are DISABLED on Windy Git, deliberately
|
||||
|
||||
Six workflows fire on `push:` and deploy to production:
|
||||
`windy-registry`, `Windy-Clone`, `WindyCloud`, `windy-mind`, `eternitas`
|
||||
(`deploy.yml`) and `windy-agent` (`release.yml`).
|
||||
|
||||
Windy Git now has a working runner, so the next synced commit to `main` would
|
||||
have attempted a **production deploy from Veron 1**. Their secrets
|
||||
(`DEPLOY_HOST` / `DEPLOY_KEY` / `VPS_SSH_KEY`) are unset here, so they would
|
||||
have failed — but they would have failed *loudly on every push*, and any step
|
||||
before the SSH step would still have run.
|
||||
|
||||
All six are now `disabled_manually`. Tests, lints and migration checks stay
|
||||
**active** — those need no secrets at all, which is why Phase 1 delivers real CI
|
||||
value immediately.
|
||||
|
||||
**Before re-enabling any deploy workflow here, decide deliberately whether
|
||||
production should be deployable from Windy Git at all.** Kit 0 deploys are
|
||||
currently manual runbooks; that is a feature, not a gap.
|
||||
|
||||
## Backups
|
||||
|
||||
`windygit-backup.timer`, nightly 04:17, `git bundle --all` + verify + `windgit`
|
||||
|
||||
Reference in New Issue
Block a user